> For the complete documentation index, see [llms.txt](https://apidocs.arionbanki.is/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://apidocs.arionbanki.is/b2b-2013-schema/b2b-services/b2b-setting-up-a-authentication-and-certificates.md).

# B2B Setting up a Authentication and Certificates

![](https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2FusEKAPJJvp3QInlOlIBO%2F0.png?alt=media)

[B2B.is](https://b2b.is)

**Introduction**

B2B is a collection of web services for people wishing to conduct banking transactions online and to gain a good overview of their personal finances. All main banking transactions can be performed using Arion Bank’s B2B services, directly from the book-keeping system at any time.

B2B is a communications tool for corporate book-keeping systems which enables the exchange of information to and from the Bank. It is used almost entirely in the book-keeping system without involving the online bank.

Implementing B2B will shorten work processes and bring greater efficiency to the book-keeping process. It saves time and helps eliminate errors. Only one system is used, i.e. your company’s book-keeping system and this reduces the risk of errors. B2B provides a real-time view of book-keeping, thus better enabling informed decision-making.

Please contact Corporate Banking at Arion Bank for further information, <arionbanki@arionbanki.is>

### B2B web services <a href="#toc478371828" id="toc478371828"></a>

B2B web services have a defined WCF endpoint with a Mutual Authentication security model. In addition the web services specified in the Icelandic Mutual Banking Scheme have defined WSE 2.0 endpoints to support backward compatibility. A username token is sent in which contains a user name, password and certificate. Information passing between the book-keeping system and the Bank is encrypted over HTTPS which ensures secure communications.

In order to use WCF B2B web services the following steps must be followed:

1. Apply for a soft certificate (isl. Búnaðarskilríki) from the firm Auðkenni (<https://www.audkenni.is/>).
2. Set up soft certificate and certification path.
3. Set up public certificate for Arion Bank.
4. Program calls to B2B web services, in the book-keeping system
5. Allow the book-keeping system to use the private key of the soft certificate
6. Each user logs into B2B and is approved/activated by Corporate Banking at Arion Bank.

This manual contains information on how certificates are set up and how users identify themselves in B2B services. You can download C# .Net sample code from <https://ws.b2b.is/Services/>

### Access management <a href="#toc478371829" id="toc478371829"></a>

B2B web services use Web Service Security (WSS) to send username token which contain a user name and password provided by Arion Bank and communications are signed using eID. The B2B services trust certificates from the firm Auðkenni hf.

The security model in the services is Mutual Authentication. The Bank’s signature certificate is used to identify the Bank to users of the service. Certificates are also needed to identify users of the service to the Bank. There are two possibilities.

* Soft certificate\
  Soft certificate is a company’s electronic certificate, which is set up in its computer system. If this type of certificate is used, the user does not need to enter a PIN number when the certificate is used as the book-keeping system automatically finds the private key of the certificate. You can download example codes for C# .Net which shows how this done on <https://ws.b2b.is/Services/>.
* Work certificate\
  Work certificate is a card, which companies provide to their employees. The certificate is for individual but also contains the company’s ID number (isl. Kennitala). The card needs to be in the card reader of the user’s computer and the employee needs to enter a 4 digit PIN number every time the certificate is used to sign something.

Companies receive both soft certificates and work certificates from Auðkenni, see [www.skilriki.is](http://www.skilriki.is/). The correct certification path for certificates needs to be in place for the certificates to work. The root at Auðkenni is called “Audkennisrot”. Certification paths can be obtained from Auðkenni where you can also find instructions on setting up soft certificates. For work certificates the user needs to have Nexus Personal software installed on their computer. This software, and instructions on how to install it, is available from Auðkenni. When work certificates are used for the first time the user will be asked whether they want to install the certification path of the Iceland root, which can be found on the card. If the user answers with yes, the certification path will be installed on the computer.

B2B web services sign all outgoing messages. If WSE technology is used, the public part of the Bank’s certificate does not need to be installed at the company using the B2B web services. If WCF technology is used more stringent requirements on security are made and the computer calling the B2B services needs to have access to the public part of the Bank’s certificate.

### Installation of soft certificate <a href="#toc478371830" id="toc478371830"></a>

### Applying for certificate at Auðkenni <a href="#toc478371831" id="toc478371831"></a>

You apply for a soft certificate from the firm Auðkenni hf (<https://www.audkenni.is>). In the application process a **private key** is installed in the computer on which the application was made. The technician in the application process receives an e-mail with a URL at Auðkenni, where they can obtain a public key certificate signed by the intermediate certificate "Traustur búnaður". The technician installs the public key in the same computer as used in the application process (the private key is on it) and the certificate is ready to be used on that computer. Note that this process may change at Auðkenni and it is therefore recommended that you follow the application process and the installation instructions from Auðkenni, when installing the certificate and the certification path.

### Exporting soft certificate <a href="#toc478371832" id="toc478371832"></a>

If you need to use the soft certificate on other computers than the one where the application was made, the certificate needs to be exported.

1\. The first step is to open a certificate store, see section “Opening a certificate store”

2\. Select a certificate which is to be exported and select "All tasks" - "Export" and click "Next"

<div data-full-width="true"><figure><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2FWgZTBXFMMyETlCHi2cl3%2Fimage008.png?alt=media&amp;token=121fbed6-fda1-4c42-beb7-62a6aa79c9cc" alt=""><figcaption></figcaption></figure></div>

<figure><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2FKgD3eMGjazlNNJyAMKDY%2Fimage010.png?alt=media&amp;token=299ff97a-d89d-4e41-bbcc-44f25b6e7287" alt=""><figcaption></figcaption></figure>

3\. Choose to export the private key.

<div data-full-width="true"><figure><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2F0eNyqWv9FlLQsspYpbTD%2Fimage012.png?alt=media&amp;token=55f31717-f24f-4ca9-9e14-fdbd0610e095" alt=""><figcaption></figcaption></figure></div>

4\. Choose to include the certification path.

<div data-full-width="true"><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2Fv56hU7lYbD8HJihjt2bb%2F6.png?alt=media" alt=""> <figure><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2Fg6F7U679KMmS6EijwBmc%2Fimage014.png?alt=media&amp;token=b07bb58d-202a-4f43-abc2-c228ac4cb4ff" alt=""><figcaption></figcaption></figure></div>

5\. The file must be locked by using a password to protect the private key.

<figure><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2FuO5RFY5dlEf7ZyDpGgkL%2Fimage016.png?alt=media&amp;token=1e415389-4595-4e89-b4c4-89fc32ed1975" alt=""><figcaption></figcaption></figure>

6\. Specify the name of the file you want to export.

<figure><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2FBKzwwzcuD8tCXoRixdTH%2Fimage018.png?alt=media&amp;token=e26533f4-3d74-44ff-a8cb-7281c1209bdd" alt=""><figcaption></figcaption></figure>

### Importing a soft certificate <a href="#toc478371833" id="toc478371833"></a>

Below are the instructions on how to import certificates into the certificate store on one computer. If the book-keeping system contacts an intermediate service responsible for sending the message and signing it, it is sufficient that the certificate is imported to the computer on which the intermediate service is installed. If, however, the book-keeping system is installed in multiple computers and each terminal is sending and signing messages, the certificate needs to be imported into every terminal. In such cases the system administrator can establish a group policy to manage importing certificates.

1\. The first step is to open a certificate store, see section “Opening a certificate store”

<div data-full-width="true"><figure><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2F2iC01dpPuxO9GQKV53J4%2Fimage020.png?alt=media&amp;token=6c9c43ca-1818-4abd-b0bd-f947956d4be9" alt=""><figcaption></figcaption></figure></div>

The root certificate “Audkennisrot” should be under Local Computer – Trusted Root Certificate Authorities (if the certificate is not in place, instructions can be found here <https://www.audkenni.is/adstod/skilriki-kortum/skilrikjakedjur/>)

<figure><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2FsHfABIUtlo7Lz0BjGJzG%2Fimage022.png?alt=media&amp;token=60b33e31-8042-4c1a-8a17-7f5127190213" alt=""><figcaption></figcaption></figure>

*The intermediate certificates should be under Local Computer - Intermediate Certification Authorities*

The location of the certificate used for signing is the responsibility of the systems administrator. The examples in this document use Local Computer – Personal

2\. In order to import a certificate into a certificate store you right click on the folder where you want to import the certificate and choose “All tasks" - “Import” and then click on “Next”

<div><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2Fpr8QksOS4tTmTheQw93X%2F11.png?alt=media" alt=""> <figure><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2F3DeOcfUg6vRWHYSfpmhr%2Fimage024.png?alt=media&amp;token=dba4b530-578a-4d93-886f-a5d7dea5f8e5" alt=""><figcaption></figcaption></figure></div>

<figure><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2F68eTfxlrx2ak89e7fzjg%2Fimage026.png?alt=media&amp;token=1fae7fdd-35ef-449e-8721-da55fa559fc7" alt=""><figcaption></figcaption></figure>

2\. Choose the file you want and then click on "Next"

<figure><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2F6AEcc3b1AF1SyVmrhQWn%2Fimage028.png?alt=media&amp;token=7c173ab0-92ca-4b03-a50e-69958a8c36a0" alt=""><figcaption></figcaption></figure>

3\. Now enter the password which was used when the certificate was exported, see “Exporting soft certificate”

<div><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2FGy793PkVVjKyBc5rn6BB%2F14.png?alt=media" alt=""> <figure><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2FMMe7P8uryh901KzpCdcD%2Fimage030.png?alt=media&amp;token=f4105468-1ffc-4d34-8ec6-a77d2258f106" alt=""><figcaption></figcaption></figure></div>

4\. Specify a location for the certificate/certification path

<figure><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2F8Zy9B72lTN2v1Us0ps1A%2Fimage032.png?alt=media&amp;token=4976c309-2df9-4dd7-b678-22a4dda9d428" alt=""><figcaption></figcaption></figure>

5\. Complete import

<div><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2FQhSWDXmxAViHy4RwROLf%2F15.png?alt=media" alt=""> <figure><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2FJbdSKXNjzxKgV4nJQ1aB%2Fimage034.png?alt=media&amp;token=0357c785-ab1e-4bac-841d-762011029e82" alt=""><figcaption></figcaption></figure></div>

### Grant rights for private key of soft certificate <a href="#toc478371834" id="toc478371834"></a>

You have to grant the system or service using soft certificate access to its private key. In this case it is most often the book-keeping system or intermediate service which calls for B2B web services.

In the case of a web/intermediate service, the user behind the Application Pool for the website must have reading access to the private key of the certificate. In most cases this is IIS\_IUSRS. For window systems it is usually the operating system user.

The first step is to open a certificate store, see section “Opening a certificate store”.

1\. Choose the certificate, right click and choose All Tasks -> Manage PrivateKeys

<div><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2FRzpehVnKUqCAgTaMysr9%2F17.png?alt=media" alt=""> <figure><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2FzGA8YX0AnvUpLmgZCfGq%2Fimage036.png?alt=media&amp;token=1fe7c468-7e3a-4f19-bf72-58fc2d754265" alt=""><figcaption></figcaption></figure></div>

2\. Give the system user read permission.

<div><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2FRT52amzdYzpRATqMQQFj%2F18.png?alt=media" alt=""> <figure><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2Fb7UmzerOR0BVjgf0iIUy%2Fimage038.png?alt=media&amp;token=a69a5e29-de9f-4491-8fdb-92493ea45ede" alt=""><figcaption></figcaption></figure></div>

### Installing public key certificate for Arion Bank <a href="#toc478371835" id="toc478371835"></a>

The security model in the services with WCF endpoints is Mutual Authentication. The Bank’s signature certificate is used to identify the Bank to users of the service. At <https://ws.b2b.is/Services/> you can download .Net C# code samples, where the public certificate is fetched automatically every time the B2B service is called. The project is called IsIT.B2B.ClaimServiceTest. There is also a code sample IsIT.B2B.PublicCertDownloader which fetches the Bank’s public key certificate. This code is also available as an exe file which can be used to fetch the Bank’s public key certificate. The public key certificate can be saved in a file (\*.cer), stored on a database or certificate store. That way you can avoid having to fetch it every time B2B service is called. However, problems occur when the Bank’s certificate expires and is renewed, which happens once a year. You would then need to get a new public key certificate and update it in the book-keeping system.

### Logging in to B2B <a href="#toc478371836" id="toc478371836"></a>

In order to connect to B2B you need a user name and password from Arion Bank and the message needs to be signed with a certificate. If using a certificate that has not been used before when communicating with the Bank with this particular user name, the certificate needs to be activated by the Bank. Before the certificate can be activated, it is necessary to call B2B service once, e.g. by requesting an exchange rate. The service will generate an error with the error code 1000. After that an employee of Corporate Banking can activate the certificate for that user. Note that the user first needs to try to make a connection and get an error message before the Bank can approve the use of the certificate. This only applies to the first time the user connects to B2B and not when renewing a certificate.

### Opening a certificate store <a href="#toc478371837" id="toc478371837"></a>

Run Microsoft Management Consol (MMC.exe)

Start → Run → MMC

Choose File → Add Remove Snap-in

<div><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2FxflTTw3C9jvrVuSXEVgZ%2F19.png?alt=media" alt=""> <figure><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2FoJoqLUiiAaBqYXvp0C11%2Fimage040.png?alt=media&amp;token=27091ba8-f15c-4058-9f60-a3f820275788" alt=""><figcaption></figcaption></figure></div>

Choose Certificates in Available snap-ins and click on “Add”.

<figure><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2Fkbjicb0MDw8l1FxbbG0t%2Fimage047.png?alt=media&amp;token=b9014fa1-5a80-4a48-a715-8ff474e680b4" alt=""><figcaption></figcaption></figure>

Choose Computer account and click on “Next”

<figure><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2FMvjt3XuNwWWtiUSyeNMH%2Fimage044.png?alt=media&amp;token=c1dda463-7f35-42bc-a542-2b8b4d0151f1" alt=""><figcaption></figcaption></figure>

Choose Personal or Local Computer and click on "Finish”

<figure><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2FEclAIme5piU8gMLlCWgC%2Fimage046.png?alt=media&amp;token=9851a9d5-bf21-42c1-9aba-3cef79a00431" alt=""><figcaption></figcaption></figure>

Click on “OK” to view the certificates in the local computer

<figure><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2Ff3MSeiJDEFiWDrZP4jGA%2Fimage047.png?alt=media&amp;token=4e0e9192-69e2-4b6e-988c-76eb8e3e2358" alt=""><figcaption></figcaption></figure>

The certificate store is then open

<figure><img src="https://2818695535-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1H6XBw80lUfS2N0XzK27%2Fuploads%2F79YuUQ0EPa490uN1I8A8%2Fimage036.png?alt=media&amp;token=98270892-2aa1-467c-b534-16ea4c082925" alt=""><figcaption></figcaption></figure>
